<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Two Virtual Routers and NATing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/two-virtual-routers-and-nating/m-p/48067#M35348</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to provide more details.&amp;nbsp; Some ISPs will not allow you to send data using an IP address that is not in the range they assigned. They consider this IP spoofing so you need to be more specific about&amp;nbsp; how the tarffic comes in and how you want it to go back out and what IPs should be involved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SKrall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Aug 2011 04:52:25 GMT</pubDate>
    <dc:creator>skrall</dc:creator>
    <dc:date>2011-08-17T04:52:25Z</dc:date>
    <item>
      <title>Two Virtual Routers and NATing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-virtual-routers-and-nating/m-p/48066#M35347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We currently utilize dual ISP's as part of our business continuity plan and it looks like we have most of our PBR's setup appropriately. I am trying to figure out a way to create a static NAT entry on ISP2 via VRF that will go to the Core Network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISP1 (L3-Outside)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ISP2 (L3-Outside2)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;Core Network (L3-Inside)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Segregated Network (L3-Inside2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to NAT a device on the core network via the ISP2 link. If that makes any sense as we have ran out of external facing IPs on the ISP1 network and I have a design requirement not to Static PAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Aug 2011 15:46:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-virtual-routers-and-nating/m-p/48066#M35347</guid>
      <dc:creator>jschelert</dc:creator>
      <dc:date>2011-08-16T15:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Two Virtual Routers and NATing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-virtual-routers-and-nating/m-p/48067#M35348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to provide more details.&amp;nbsp; Some ISPs will not allow you to send data using an IP address that is not in the range they assigned. They consider this IP spoofing so you need to be more specific about&amp;nbsp; how the tarffic comes in and how you want it to go back out and what IPs should be involved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SKrall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Aug 2011 04:52:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-virtual-routers-and-nating/m-p/48067#M35348</guid>
      <dc:creator>skrall</dc:creator>
      <dc:date>2011-08-17T04:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: Two Virtual Routers and NATing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-virtual-routers-and-nating/m-p/48068#M35349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got it to work fairly quickly by utilized two Virtual Routers and getting the NATing setup between zones. The most challenging part was the U Turn needed to access the site from the inside / out.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Aug 2011 17:34:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-virtual-routers-and-nating/m-p/48068#M35349</guid>
      <dc:creator>jschelert</dc:creator>
      <dc:date>2011-08-24T17:34:03Z</dc:date>
    </item>
  </channel>
</rss>

